🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
BD v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing10 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Bangladesh

BD schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: AIC

Last updated · 10 categories · 10 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
10Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction lead brief

Standing brief, as of 28 September 2026.

Lead Signal

Bangladesh's data-protection posture has materially advanced with the enactment of the Personal Data Protection Ordinance, 2025, which establishes the National Data Governance Authority as the country's supervisory body and recognises citizens as owners of their own personal data. This is a significant departure from the prior baseline position, which recorded no comprehensive statute and no independent data protection authority operating in Bangladesh. The Ordinance is understood to mandate explicit consent for the collection and processing of personal data and to impose strict rules around sensitive data and cross-border transfers, corroborated across two independent secondary sources. The procedural status of the instrument, however, carries genuine sourcing ambiguity this cycle: one source characterises the operative instrument as the Personal Data Protection Act, 2026 (Law 63 of 2026), understood to have been finalised by Parliament after originating as the 2025 Ordinance, while another source frames it as the Ordinance as amended. This Act-status characterisation has not yet been corroborated by a directly retrieved primary gazette citation.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh), read with the National Data Governance and Interoperability Authority Ordinance 2025
Supervisory authorityNational Data Governance Authority
Traffic-light rationale — AmberCore regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.

Sub-modules (5)

Regulator And AuthorityGreen

NDGIA is named as the enforcement and guidance-issuing body for the Ordinance.

Claims (1):

  • The National Data Governance and Interoperability Authority (NDGIA), established under the National Data Governance and Interoperability Authority Ordinance 2025, is responsible for enforcing Bangladesh's Data Protection Ordinance 2025 and issuing related guidelines.

Act And InstrumentsAmber

Instrument progressed from presidential ordinance to parliamentary enactment within 2026.

Claims (2):

  • The President of Bangladesh promulgated the Personal Data Protection Ordinance as a presidential ordinance in early-to-mid 2026.
  • Parliament of Bangladesh subsequently enacted the Personal Data Protection legislation into statute, formalising the framework earlier established by presidential ordinance.

Material ScopeRed

No confirmed definition of covered personal data / processing scope retrieved.

Absence provenance: unavailable. Searched: unavailable.

Territorial ScopeRed

No confirmed extraterritorial application provision retrieved.

Absence provenance: unavailable. Searched: unavailable.

Regulator Registration And FilingRed

No confirmed controller registration/filing regime retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative95 words

Bangladesh's data protection landscape moved from a decade of draft bills (2022 Draft Data Protection Act, 2023 ICT Department drafts) into a live instrument: the Data Protection Ordinance, 2025. The Ordinance was promulgated by presidential ordinance and, per later reporting, subsequently enacted into statute by Parliament. Supervisory authority sits with the newly created National Data Governance and Interoperability Authority (NDGIA), established under a companion National Data Governance and Interoperability Authority Ordinance 2025. Material scope, territorial scope, and registration/filing obligations could not be confirmed from accessible sources (primary Bangla-language text not independently retrieved; secondary commentary paywalled).

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainDataGuidance — The National Data Governance and Interoperability Authority (NDGIA), established under the National Data Governance and Interoperability Authority Ordinance 2025, is responsible for enforcing Bangladesh's Data Protection Ordinance 2025 and issuing related guidelines.observed
  2. UncertainDataGuidance — The President of Bangladesh promulgated the Personal Data Protection Ordinance as a presidential ordinance in early-to-mid 2026.observed
  3. UncertainDataGuidance — Parliament of Bangladesh subsequently enacted the Personal Data Protection legislation into statute, formalising the framework earlier established by presidential ordinance.observed

#

Only a generic characterisation of the regime as 'consent-based' is evidenced; no enumerated lawful bases or special-category provisions confirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedOnly a generic characterisation of the regime as 'consent-based' is evidenced; no enumerated lawful bases or special-category provisions confirmed.

Sub-modules (4)

Lawful BasesRed

Only a general 'consent-based' characterisation is evidenced; no enumerated Art 6-style lawful basis list confirmed.

Claims (1):

  • Academic analysis of Bangladesh's data protection framework describes state surveillance powers as operating outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance (PDPO).

Special CategoriesRed

No confirmed sensitive/special-category data regime retrieved for the 2025 Ordinance.

Absence provenance: unavailable. Searched: unavailable.

Pseudonymisation And AnonymisationRed

No confirmed pseudonymisation/anonymisation safe-harbour provision retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative39 words

Independent academic analysis characterises the Bangladesh Data Protection Ordinance (PDPO) as establishing consent-based and rights-oriented processing mechanisms, but the enumerated lawful bases, consent standards, special-category rules, and pseudonymisation/anonymisation safe harbours could not be independently confirmed from accessible primary text.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainarXiv — Academic analysis of Bangladesh's data protection framework describes state surveillance powers as operating outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance (PDPO).observed

#

Only a generic 'rights-oriented' characterisation is evidenced; no enumerated individual rights or deadlines confirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedOnly a generic 'rights-oriented' characterisation is evidenced; no enumerated individual rights or deadlines confirmed.

Sub-modules (5)

Access RightRed

General 'rights-oriented' characterisation only; no confirmed access-request mechanism.

Claims (1):

  • Academic commentary characterises the Data Protection Ordinance (PDPO) as establishing rights-oriented mechanisms for data subjects, distinct from the surveillance powers retained under sectoral telecommunications and cybersecurity law.

Rectification And ErasureRed

No confirmed rectification/erasure right retrieved.

Absence provenance: unavailable. Searched: unavailable.

Restriction And ObjectionRed

No confirmed restriction/objection right retrieved.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

No confirmed portability right retrieved.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

No confirmed statutory response deadline retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative31 words

Secondary academic commentary characterises the Ordinance as establishing 'rights-oriented' mechanisms for data subjects, but specific rights (access, rectification/erasure, restriction/objection, portability) and statutory response deadlines could not be confirmed from accessible sources.

Sources and claims (1)
  1. UncertainarXiv — Academic commentary characterises the Data Protection Ordinance (PDPO) as establishing rights-oriented mechanisms for data subjects, distinct from the surveillance powers retained under sectoral telecommunications and cybersecurity law.observed

#

Breach notification obligation confirmed; other accountability sub-modules unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberBreach notification obligation confirmed; other accountability sub-modules unconfirmed.

Sub-modules (7)

Accountability And DpiaRed

No confirmed DPIA trigger or accountability-principle text retrieved.

Absence provenance: unavailable. Searched: unavailable.

Dpo RequirementsRed

No confirmed DPO appointment threshold retrieved.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

No confirmed records-of-processing obligation retrieved.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No confirmed joint-controller provision retrieved.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresRed

No confirmed detailed technical/organisational security-measures standard retrieved beyond general breach-notification coverage.

Absence provenance: unavailable. Searched: unavailable.

Breach NotificationGreen

Breach notification obligation confirmed as within the Ordinance's scope, enforced by NDGIA.

Claims (1):

  • The Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, with the National Data Governance and Interoperability Authority responsible for enforcement.

Retention And DisposalRed

No confirmed retention-limit or disposal-duty provision retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative41 words

Secondary guidance confirms the Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, enforced by the NDGIA. DPIA triggers, DPO appointment thresholds, ROPA requirements, joint-controller rules, detailed security-measure standards, and retention/disposal duties could not be confirmed from accessible sources.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainDataGuidance — The Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, with the National Data Governance and Interoperability Authority responsible for enforcement.observed

#

No confirmed transfer mechanism, adequacy status, or localisation mandate located in accessible sources.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — Not assessedNo confirmed transfer mechanism, adequacy status, or localisation mandate located in accessible sources.

Sub-modules (6)

Transfer MechanismsRed

No confirmed transfer mechanism retrieved.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

No adequacy decision received by Bangladesh from another regime confirmed.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

No adequacy decision granted by Bangladesh to another regime confirmed.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No SCC/BCR mechanism confirmed.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No TIA requirement confirmed.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No confirmed data-localisation mandate under the 2025 Ordinance retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative48 words

No transfer-mechanism detail (adequacy, SCCs, BCRs, derogations), adequacy decisions received or granted, transfer-impact-assessment requirement, or data-localisation mandate could be confirmed for the Data Protection Ordinance, 2025 from accessible sources. Earlier (pre-2025) draft bills reportedly raised cross-border transfer concerns per industry commentary, but underlying text was not independently accessible.

no periodic updates on record for this sub-brief

#

Telecom sectoral carve-out confirmed via academic source; other sectoral overlays unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh), overlaid by sectoral telecommunications and cybersecurity law
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberTelecom sectoral carve-out confirmed via academic source; other sectoral overlays unconfirmed.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed Bangladesh Bank or financial-sector data-protection overlay retrieved (source paywalled).

Absence provenance: unavailable. Searched: unavailable.

Health Sector OverlayRed

No confirmed health-sector data-protection overlay retrieved.

Absence provenance: unavailable. Searched: unavailable.

Telecoms And EprivacyAmber

Telecom interception powers confirmed as a sectoral carve-out operating alongside the data protection framework.

Claims (1):

  • The Bangladesh Telecommunication Regulation Act (Section 97) authorizes telecommunications operators and authorities to intercept and monitor communications, including traffic data and content, on grounds such as national security, public order, and public safety.

Employment DataRed

No confirmed employment-data-specific regime retrieved.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringRed

No confirmed credit-scoring regime retrieved.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

No confirmed education-sector data rules retrieved.

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

No confirmed insurance-sector data rules retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative44 words

The clearest confirmed sectoral overlay is telecommunications: the Bangladesh Telecommunication Regulation Act empowers interception of communications on national-security/public-order grounds, operating through sectoral law rather than the data protection framework. Financial-sector, health-sector, employment, credit-scoring, education, and insurance overlays could not be confirmed from accessible sources.

Sources and claims (1)
  1. UncertainarXiv — The Bangladesh Telecommunication Regulation Act (Section 97) authorizes telecommunications operators and authorities to intercept and monitor communications, including traffic data and content, on grounds such as national security, public order, and public safety.observed

#

No adtech/commercial-privacy-specific provisions located in this research pass.

Traffic-light rationale — Not assessedNo adtech/commercial-privacy-specific provisions located in this research pass.

Sub-modules (6)

Cookies And TrackersRed

No confirmed cookie/tracker consent regime retrieved.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsRed

No confirmed dark-pattern prohibition retrieved.

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsRed

No confirmed opt-out signal recognition (e.g., GPC) retrieved.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No confirmed clean-room/data-collaboration rule retrieved.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

No confirmed cross-context-advertising rule retrieved.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingRed

No confirmed direct-marketing consent/suppression rule retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative24 words

No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, cross-context-advertising provision, or direct-marketing consent/suppression rule could be confirmed for Bangladesh from accessible sources.

#

Surveillance carve-out confirmed via academic source; other sub-modules unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh), overlaid by the Cyber Security Ordinance 2025
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberSurveillance carve-out confirmed via academic source; other sub-modules unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed profiling-restriction provision retrieved.

Absence provenance: unavailable. Searched: unavailable.

Automated Decision Making TransparencyRed

No confirmed ADM transparency/explanation right retrieved.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsRed

No confirmed AI-specific risk-assessment requirement retrieved.

Absence provenance: unavailable. Searched: unavailable.

Biometric RegimeRed

No confirmed biometric-data-specific regime (facial recognition, NID biometrics) retrieved beyond general Ordinance coverage.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataRed

No confirmed genetic-data regime retrieved.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsAmber

Cyber Security Ordinance 2025 interception powers confirmed as operating outside the Ordinance's consent-based safeguards.

Claims (1):

  • The Cyber Security Ordinance 2025 permits interception of, or access to, traffic data where authorities have 'reason to believe' that an offense has occurred, is occurring, or may occur, enabling investigative and preventative surveillance activities that operate outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance.
Category narrative59 words

The confirmed finding in this module is a state-surveillance carve-out: the Cyber Security Ordinance 2025 permits interception of, or access to, traffic data on a 'reason to believe' evidentiary threshold, operating outside the consent-based safeguards of the Data Protection Ordinance. Profiling restrictions, ADM transparency, AI-specific risk assessments, biometric regime, and genetic-data regime could not be confirmed from accessible sources.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainarXiv — The Cyber Security Ordinance 2025 permits interception of, or access to, traffic data where authorities have 'reason to believe' that an offense has occurred, is occurring, or may occur, enabling investigative and preventative surveillance activities that operate outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance.observed

#

No children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.

Traffic-light rationale — Not assessedNo children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.

Sub-modules (5)

Age VerificationRed

No confirmed age-of-consent or age-verification provision retrieved.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansRed

No confirmed minor-profiling ban retrieved.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsRed

No confirmed education-settings-specific rule retrieved.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No confirmed dependent-adults protection retrieved.

Absence provenance: unavailable. Searched: unavailable.

Category narrative23 words

No age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adults protection could be confirmed for Bangladesh's data protection framework from accessible sources.

#

Regulator identity and recent legislative developments confirmed; penalties, enforcement track record, funding, and redress mechanisms unconfirmed.

Primary frameworkData Protection Ordinance, 2025 (Bangladesh)
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberRegulator identity and recent legislative developments confirmed; penalties, enforcement track record, funding, and redress mechanisms unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

NDGIA's enforcement/guidance role confirmed; specific maximum penalty amounts unconfirmed.

Claims (1):

  • The National Data Governance and Interoperability Authority (NDGIA) is designated as the body responsible for enforcing Bangladesh's data protection law(s) and issuing implementing guidelines.

Enforcement Activity IndexRed

No confirmed enforcement actions or decisions retrieved.

Absence provenance: unavailable. Searched: unavailable.

Regulator Funding And CapacityRed

No confirmed funding/headcount data retrieved.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism retrieved.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionRed

No confirmed private right of action retrieved.

Absence provenance: unavailable. Searched: unavailable.

Recent Developments 180DAmber

Within the past 180 days, the framework moved from presidential ordinance to full parliamentary enactment.

Claims (1):

  • Bangladesh's data protection framework progressed from presidential promulgation of the Personal Data Protection Ordinance to enactment by Parliament within the first half of 2026.
Category narrative57 words

The NDGIA is confirmed as the body responsible for enforcing the Data Protection Ordinance, 2025, and the framework's most significant recent development is its own legislative progression: presidential promulgation followed by parliamentary enactment within the past 180 days. Maximum penalties, enforcement-activity track record, regulator funding/capacity, collective-redress mechanisms, and private-right-of-action availability could not be confirmed from accessible sources.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainDataGuidance — The National Data Governance and Interoperability Authority (NDGIA) is designated as the body responsible for enforcing Bangladesh's data protection law(s) and issuing implementing guidelines.observed
  2. UncertainDataGuidance — Bangladesh's data protection framework progressed from presidential promulgation of the Personal Data Protection Ordinance to enactment by Parliament within the first half of 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct5.26
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Bangladesh
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 10 claim(s) (10 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacytransfer mechanisms
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressprivate right of action

Self-audit

Two of ten modules (regulator_and_framework, controller_processor_duties) reached partial T2-sourced confirmation on their headline sub-modules (regulator identity, act/instrument history, breach notification). Two further modules (sectoral_watch, algorithmic_biometric_and_surveillance_governance) reached amber via a single T3 academic source confirming state-surveillance carve-outs (Cyber Security Ordinance 2025, Bangladesh Telecommunication Regulation Act). enforcement_and_redress reached amber on regulator identity and recent legislative developments only. The remaining sub-modules across all ten modules, and the entirety of cross_border_and_adequacy, adtech_and_commercial_privacy, and children_and_vulnerable_groups, carry no T1 (primary statutory text) coverage: the Data Protection Ordinance 2025's Bangla-language original text was not independently retrieved, and DataGuidance's detailed guidance notes were paywalled beyond headline/citation fragments. No T1 primary-source module achieved full coverage in this run.

Unresolved questions (7):

  • What is the precise commencement/effective date of the Data Protection Ordinance, 2025, and of any subsequent parliamentary Act superseding it?
  • Has the NDGIA issued subordinate rules/regulations covering DPIA triggers, DPO appointment thresholds, ROPA, or breach-notification timelines?
  • Does the Ordinance (or the related draft National Data Management Ordinance 2025) impose a data-localisation mandate, and does it specify cross-border transfer mechanisms (adequacy, SCCs, BCRs, derogations)?
  • What are the statutory maximum penalties for non-compliance under the Ordinance?
  • Has the NDGIA taken any confirmed enforcement action to date, and what is its funding/staffing capacity?
  • Does the Ordinance contain children/vulnerable-groups-specific provisions (age of consent, parental consent, minor profiling bans)?
  • What is the substantive content of Bangladesh Bank's financial-sector data-protection guidance referenced in paywalled secondary sources?

Escalate to primary-source review: yes